phpMyAdmin HTTP Response Splitting and File Inclusion Vulnerabilities
Last Update Date:
28 Jan 2011
Release Date:
26 Mar 2009
5444
Views
RISK: Medium Risk
Two vulnerabilities have been identified in phpMyAdmin, which could be exploited by attackers to disclose sensitive information or bypass security restrictions. These issues are caused by input validation errors in the BLOB streaming feature, which could allow arbitrary file inclusion and HTTP header inject attacks.
Impact
- Information Disclosure
System / Technologies affected
- phpMyAdmin verisons prior to 3.1.3.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to phpMyAdmin verison 3.1.3.1 :
http://www.phpmyadmin.net/home_page/downloads.php
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with